top of page

LGPD - General Law for the Protection of Personal Data and IT processes

Law 13.709/2018 - Approved in August 2018 and effectively in force from August 2020.


Based on the European General Data Protection Regulation (GDPR), this law was created to provide legal support.

to Brazilian citizens regarding the processing of data of an identified or identifiable natural person.


Article 5 states that "processing" is any operation performed on personal data, such as those relating to collection,

production, reception, classification, use, access, reproduction, transmission, distribution, processing, archiving, storage, elimination, evaluation or control of information, modification, communication, transfer, dissemination or extraction.

 

DATA PROCESSING AGENTS AND NATIONAL DATA PROTECTION AUTHORITY
Controller and operator are the agents responsible for processing personal data, who must maintain a record of processing operations when based on legitimate interest - article 37.
These agents must adopt security measures (from conception to execution of the product/service), protecting personal data from unauthorized access, accidental or unlawful destruction, loss, alteration, communication or dissemination, or any other occurrence resulting from improper or unlawful processing - article 46.

Article 50 recommends that processing agents formulate good practice and governance rules regarding organizational structure, operating procedures, security norms, technical standards, specific obligations, and mechanisms for oversight and risk mitigation, among other measures related to data processing.


ANPD (National Data Protection Authority) is the entity responsible for drafting guidelines for the national policy on personal data protection and privacy, as well as issuing regulations and procedures, ensuring the protection of such data, and conducting oversight and the application of prescribed penalties.

 

Minimum technical standards may be defined by the competent authority.

Personal data processing systems must meet security, good practice, and governance requirements, as well as the principles of the LGPD and the standards set by the competent authority (Article 49).

 

Harm caused to the data subject gives rise to joint civil and criminal liability for the controller and the operator, as well as the obligation to redress the damages (Article 42), without prejudice to administrative sanctions.

 

The competent authority may require the controller to produce a personal data protection impact assessment regarding its data processing operations (Article 38).

 

>> Report – description of collected data, collection methodology, information security assurances, measures, safeguards, and risk mitigation mechanisms.

Penalties

The LGPD establishes in article 52:

  • Warning;

  • Obligation to disclose the incident;

  • Deletion of personal data;

  • A fine of up to 2% of the revenue of the private legal entity, excluding taxes, and limited, in total, to R$50 million per infraction.

  • Penalties do not replace the application of administrative, civil or criminal sanctions provided for in specific legislation - article 52, §2.

However, in addition to the direct financial loss, the exposure caused by making the infraction public also damages its credibility by leaving its clients' personal data vulnerable.

COMMERCIAL AND CONSUMER RELATIONS

The LGPD (Brazilian General Data Protection Law) will have a major impact on commercial and consumer relations, which require data collection, given the increasing processing of personal data of clients/consumers to create profiles and identify various information, consumption habits, and financial/credit conditions.

What is the impact of the LGPD (Brazilian General Data Protection Law) on IT processes?

Key issues in the Information Technology and Compliance sector have undoubtedly been privacy and data protection.

It is necessary to manage issues involving your databases and other information repositories, carrying out all security procedures in their collection, storage, and processing.

Several basic principles need to be taken into account in the processes stemming from this concept:

1) Proactive, not reactive; preventive, not corrective: To foresee/anticipate events that could interfere with and/or compromise privacy.

2) Privacy: Standard - providing security and protection, where processing should be treated as an exception and conditional upon prompt authorization from the data subject. Furthermore, it should incorporate privacy tools to reduce the effort and strain of future compliance with data protection rules. Privacy becomes part of the solution itself, not an add-on.

3) End-to-end security: Ensuring the security of information from capture to deletion or sharing.

4) Visibility and transparency: These need to be applied from the outset. The terms and conditions of use and privacy policy must be clearly displayed by the data controller, highlighting all relevant information involving the mitigation or relaxation of any right.

The Importance of Data Visibility and Management
Undoubtedly, the law will affect how IT professionals handle, collect, and process data.

– Data transfer: data that requires transfer must be encrypted, and the encryption must be irreversible.

 

Regarding data transfer, there are clear requirements and adequate controls in place to ensure compliance with applicable data protection regulations when personal data is transferred by any means.


There should be additional protection in the transmission of data, whether at an individual or aggregate level, through the use of specific IT digital processes, such as encryption of transferred data or the use of secure FTP (File Transfer Protocol) transfer platforms.

Technical aspects of data transfer in relation to LGPD/GDPR

We know that the standard IBM FTP server, when transferring personal data, does not comply with the LGPD/GDPR (Brazilian General Data Protection Law).

So, what are the basic requirements for FTP to meet this compliance?

  • Use secure protocols, SFTP or FTPS with strong cipher suites.

  • Encrypt the stored data

  • Always require authentication.

  • Audit and maintain a record of transfers and accesses.

It is important to highlight that adapting to the LGPD (Brazilian General Data Protection Law) requires new investments in IT management, such as staff training, new processes, and technology requirements that have been ignored until now.

Secure transfer of personal data is becoming an essential operational business process in IT.

Copyright © 2026 Workers Informática Ltda

  • Facebook
  • Twitter
  • LinkedIn
bottom of page